THE article discusses the MacSync Stealer, a macOS information thief that utilizes a rotating infrastructure for payload delivery and data exfiltration. Microsoft Defender Experts analyzed behavioral patterns associated with the malware, identifying over 30 domains linked through recurring network behaviors and execution traits.
Key findings include:
- Attackers initiate execution through social engineering tricks, using Terminal commands to retrieve and execute malicious scripts.
- The malware extracts sensitive data, including credentials and stored files, then stages the data before exfiltrating it through HTTP PUT requests.
- Behavioral traits persist despite frequent domain changes, allowing defenders to focus on consistent request patterns and execution methods for identifying and mitigating this threat.
Mitigation strategies emphasize user education to prevent unauthorized command execution, monitoring for suspicious activity linked to the malware's behavior, and leveraging advanced detection strategies targeting specific command-line patterns and file upload behaviors.